13629 vulnerabilidades · Web Orden: CVSS EPSS Año ID
CVE-2025-20240
Cisco IOS XE Software Web Networking
6.1
MEDIUM
EPSS
0.0%
2025 CWE-692 1 PoC

A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting attack (XSS) on an affected device. This vulnerability is due to improper sanitization of user-supplied input. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to execute a reflected XSS attack and steal user cookies from the affected device.

CVE-2025-63735
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the the captive-portal endpoint selfguestpass/guestAccessSubmit.jsp.

CVE-2025-29512
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Cross-Site Scripting (XSS) vulnerability in NodeBB v4.0.4 and before allows remote attackers to store arbitrary code and potentially render the blacklist IP functionality unusable until content is removed via the database.

CVE-2025-61454
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoint. Unsanitized input in the /search parameter is directly reflected back into the response HTML, allowing attackers to execute arbitrary JavaScript in the browser of a user who visits a malicious link or submits a crafted request.

CVE-2025-56313
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the /publix/run endpoint of JATOS 3.7.1 through 3.9.6 (inclusive). This allows remote attackers to execute arbitrary JavaScript in a user's web browser by including a malicious payload in the "code" URL parameter. When an authenticated admin user accesses the study's URL, the malicious script gets interpreted and executes within their browser, which can lead to unauthorized actions, account compromise, and privilege escalation.

CVE-2025-4429
Gearside Developer Dashboard Web Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The Gearside Developer Dashboard WordPress plugin through 1.0.72 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-63211
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5.0-10, allows attackers to execute arbitrary code via the addName parameter to the /vbc/core/userSetupDoc/userSetupDoc endpoint.

CVE-2025-29573
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Cross-Site Scripting (XSS) vulnerability exists in Mezzanine CMS 6.0.0 in the "View Entries" feature within the Forms module.

CVE-2025-1382
Contact Us By Lord Linus Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

The Contact Us By Lord Linus WordPress plugin through 2.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.

CVE-2025-63499
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter.

CVE-2025-50107
Oracle Universal Work Queue Web Database
6.1
MEDIUM
EPSS
0.1%
2025 1 PoC

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Request handling). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized updat

CVE-2025-56762
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php.

CVE-2025-7369
WP Shortcodes Plugin — Shortcodes Ultimate Web Windows
6.1
MEDIUM
EPSS
0.0%
2025 CWE-352 1 PoC

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.4.2. This is due to missing or incorrect nonce validation on the preview function. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link. In combination with CVE-2025-7354, it leads to Reflected Cross-Site Scripting.

CVE-2025-60448
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in Emlog Pro 2.5.19. The vulnerability exists due to insufficient validation of SVG file uploads in the /admin/media.php component, allowing attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed.

CVE-2025-1286
Download HTML TinyMCE Button Web Windows
6.1
MEDIUM
EPSS
0.3%
2025 1 PoC

The Download HTML TinyMCE Button WordPress plugin through 1.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

CVE-2025-29015
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Code Astro Internet Banking System 2.0.0 is vulnerable to Cross Site Scripting (XSS) via the name parameter in /admin/pages_account.php.

CVE-2025-65215
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product_expiry/add-supplier.php via the Supplier Name field.

CVE-2025-60452
Software Genérico Web
6.1
MEDIUM
EPSS
0.0%
2025 1 PoC

A stored Cross-Site Scripting (XSS) vulnerability has been discovered in MetInfo CMS version 8.0. The vulnerability exists in the download management module, specifically in the app\system\download\admin\download_admin.class.php component. The vulnerability allows attackers to upload malicious SVG files containing JavaScript code that executes when the uploaded file is viewed or accessed by users.

CVE-2025-3662
FancyBox for WordPress Web Windows
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

The FancyBox for WordPress plugin before 3.3.6 does not escape captions and titles attributes before using them to populate galleries' caption fields. The issue was received as a Contributor+ Stored XSS, however one of our researcher (Marc Montpas) escalated it to an Unauthenticated Stored XSS

CVE-2025-44183
Software Genérico Web
6.1
MEDIUM
EPSS
0.2%
2025 1 PoC

Phpgurukul Vehicle Record Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php via the name, email, and mobile parameters.